#VU124138 CRLF injection in Roundcube Webmail
Published: March 19, 2026 / Updated: March 19, 2026
Roundcube Webmail
Roundcube
Description
The vulnerability allows a remote user to perform IMAP command injection and bypass CSRF protections.
The vulnerability exists due to improper input validation in mail search functionality when handling search queries. A remote user can send a specially crafted search request containing malicious IMAP commands to execute arbitrary commands on the IMAP server and bypass CSRF restrictions.